The Most Common Healthcare Security Problem Could Be Right Under Your Nose

The Most Common Healthcare Security Problem Could Be Right Under Your Nose

The question is this: How can healthcare organizations protect themselves against threats when most originate from within their own walls?

Verizon’s "2018 Data Breach Investigation Report" did not paint a pretty picture for the state of healthcare data security. Not only is the healthcare industry the most vulnerable to cyberattacks, but it’s also the only industry in which more data breaches are caused by internal actors (56 percent) than external ones (43 percent).

This disparity stems from a combination of factors — not the least of which is the complex communication that’s involved in delivering patient care. In other industries, such as banking, limiting access to sensitive information is usually simple and role-based. By comparison, healthcare professionals must share protected health information (PHI) not only with one another, but also with third-party entities and individuals, such as specialists and insurance providers.

With so many outside parties having such unrestricted access to patient information, it is no wonder the risk of a data breach is so high. The question is this: How can healthcare organizations protect themselves against threats when most originate from within their own walls?

The Threats Within Your Organization

The U.S. Computer Emergency Readiness Team (US-CERT) classifies an insider threat as an “employee, contractor, or other business partner who has or had authorized access to an organization's network, system, or data and intentionally misused that access to negatively affect the confidentiality, integrity, or availability of the organization's information or information systems.”

Often, people bucket insider threats into two categories — “malicious” or “accidental” — but there is also a third category: “non-malicious.” It might seem like semantics, but it is important to know how to best protect your organization against each type:

1. Take Measures Against Vengeful Employees

A malicious insider threat is one that deliberately aims to harm your organization, whether that involves stealing patient and financial information, sabotaging your IT infrastructure, committing wide-scale fraud, or quietly spying on your organization. After analyzing more than 800 malicious attacks, US-CERT could not discern a standard profile for malicious insider threats.

Unlike a remote hacker, who uses technical means to infiltrate your system, a malicious insider will adopt more insidious means, such as social engineering and exploiting business processes to gain access. Because malicious insiders all operate differently and cannot be profiled, preventing their attacks can prove very difficult.

That said, you can mitigate your organization’s risk by remedying weaknesses in security policies and holding awareness training. Watch for red flags that could warn you of an employee’s malicious intent, such as downloading abnormal data and bragging about hacking abilities. Also, teach employees how to spot these signs, and create a confidential model for reporting them so employees feel more confident doing so.

For even stricter security precautions, use advanced data tracking and analytics to keep an eye on data anomalies and monitor any suspicious activity on the network. When used correctly, technology and comprehensive security policies will be your strongest tools against a malicious attack.

2. Combat User Error

Employees who are an accidental insider threat have no intent to break policy or harm your organization but instead fall victim to the pitfalls of simple human error.

Even with high-end spam filters and redundancies in place, healthcare employees continue to frequently make mistakes that leave them vulnerable to phishing attacks. An overconfidence in their ability to spot scams coupled with sophisticated techniques like display name spoofing leads employees to trust emails that come from seemingly legitimate sources.

Combat accidental threats by reminding employees that it only takes a single click for hackers to gain access to the system. Regular training programs will keep employees vigilant, and routine policy reviews will make sure they fully understand the rules. You can never overstate the risk involved with growing complacent.

Also, boost employee awareness by providing them with security tools that block suspicious websites from loading and prevent them from unwittingly downloading suspicious email files. If employees’ devices ask permission before completing such actions, they will be forced to think deliberately about the risks.

3. Prioritize Policy Over Politeness

Non-malicious insider threats exploit certain policies and practices, too, but not with the intent to harm the organization. In many cases, this type of threat occurs when an employee breaks a policy to help a fellow employee — for instance, sharing a password. While the employee had good intentions, he or she has now created an entry point for a potential malicious actor.

For example, when Edward Snowden stole data from the National Security Agency with the intent to compromise it, he gained much of his access by fooling co-workers into sharing their login credentials. As non-malicious threats, the co-workers wittingly broke policy to help a colleague in need and unwittingly paved the way for extensive data theft. These same co-workers could have been the NSA’s frontline defense against Snowden — if they had reported his request to violate a policy.

To avoid similar situations, make sure employees are aware of updated security policies through routine awareness training. Also, stress the importance of policy over politeness, and encourage them to report any violations they witness. Snowden’s co-workers might have questioned whether it was a good idea to give him access to their accounts but did so anyway to avoid seeming impolite. When everyone agrees policy is the most important factor, politeness is no longer a hindrance to security.

As hackers discover more sophisticated ways to compromise organizations’ data security, the rate of ransomware, data theft, and other cyberattacks will continue to increase. As the most frequently targeted industry, healthcare organizations would do well to pay special attention to the telltale signs of security threats — from both outside and inside their walls.

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3